• v1.1.0 d96f25b1d6

    ExploreDNS v1.1.0
    Deploy / deploy (push) Successful in 2m26s
    CI / docker (push) Successful in 10m19s
    Release / docker (push) Successful in 1m32s
    Release / binaries (push) Successful in 2m55s
    CI / test (push) Successful in 10m4s
    Stable

    gary released this 2026-07-07 15:16:11 +00:00 | 4 commits to main since this release

    The web interface grows up: this release brings the dns.squish.net-style
    traversal detail tree and a geolocated server map to the browser, plus
    operational features for running ExploreDNS as a public service — rate
    limiting, optional usage reporting, and automated release engineering.

    Highlights

    Live traversal detail tree. The web UI now renders every query as it
    happens in a refid-numbered tree mirroring the original dns.squish.net
    detail view: status chips per node (referral / answered / error), glue
    resolution subtrees collapsed behind per-node "show resolve" toggles,
    italic -- completed earlier markers for fast-mode reuse, and a raw
    event log behind a toggle for debugging.

    Server map. After each traversal the server fingerprints every
    nameserver it encountered (version.bind) and the UI plots them on an
    OpenStreetMap/Leaflet map with a Country / City / Servers / Software
    table beneath — geolocation happens client-side via geojs.io, so there
    are no API keys and no server-side tracking. Also available raw at
    GET /api/traverse/{id}/servers.

    Public-service guardrails. Traversal starts are now rate-limited per
    client IP (default 30/hour, tunable via EXPLOREDNS_RATE_LIMIT,
    Fly-Client-IP/X-Forwarded-For aware) on top of the existing
    concurrency cap and hard timeout. Direct localhost use is exempt, so
    local workflows stay unthrottled.

    Optional usage reporting. Set EXPLOREDNS_WEBHOOK_URL and the server
    POSTs a JSON event when a traversal starts and another when it completes
    (duration, status, result count, and the summary). Delivery is
    fire-and-forget with a short timeout and one retry — a slow or dead
    receiver can never delay a user's traversal. Off by default; exact
    payload shapes are documented in the README.

    Release engineering. exploredns --version / -V reports the build
    version (also in GET /api/health, alongside the Fly region serving the
    request). From this release onward, every v* tag automatically builds
    and attaches binaries for Linux (amd64/arm64), macOS (amd64/arm64), and
    Windows (amd64) with SHA256SUMS, pushes version-tagged Docker images,
    and deploys the hosted instance.

    Plus: a favicon — the delegation tree in 32 pixels, green leaf for
    the answered path.

    Upgrading from v1.0.0

    • No CLI changes; output and flags are unchanged.
    • Web API: rate limiting is on by default (30 traversals/hour per
      client IP → HTTP 429 beyond that). Raise or lower it with
      EXPLOREDNS_RATE_LIMIT="N/duration".
    • /api/health now includes version (and region when running on
      Fly.io).
    • New endpoint: GET /api/traverse/{id}/servers; SSE streams emit a
      servers stage event when fingerprints are ready.

    Install

    go install gitea.hansenits.com.au/hits/ExploreDNS/cmd/exploredns@v1.1.0
    go install gitea.hansenits.com.au/hits/ExploreDNS/cmd/server@v1.1.0
    
    Downloads
  • v1.0.0 391d849a5f

    ExploreDNS v1.0.0
    Deploy / deploy (push) Successful in 1m26s
    CI / test (push) Successful in 2m35s
    CI / docker (push) Successful in 13m10s
    Stable

    gary released this 2026-07-07 12:19:08 +00:00 | 9 commits to main since this release

    First stable release. ExploreDNS is a self-contained Go reimplementation of
    James Ponder's classic dnstraverse
    (the engine behind dns.squish.net): it walks the DNS delegation tree from the
    root down and, instead of stopping at the first answer, explores every
    resolution path a real iterative resolver could take — reporting each
    outcome with the probability that a real-world query would end up there, so
    broken delegations, lame referrals, and missing glue surface even when a
    domain "mostly works".

    Highlights

    Faithful dnstraverse traversal semantics. The engine was verified against
    live runs of the original Ruby engine across answered, NXDOMAIN, null-MX,
    CNAME-restart, and glueless-delegation domains, with matching results:

    • Strictly non-recursive (RD=0) queries at every delegation step
    • Per-nameserver and per-IP branching with probability split 1/n at each
      fan-out; aggregated outcomes always sum to 100%
    • Bailiwick-aware response caching — out-of-bailiwick records are discarded,
      lame referrals are detected and reported
    • Glueless NS resolution via sub-traversals from the branch cache (never the
      local resolver), with no glue and loop dead-ends carrying their
      probability into the results
    • CNAME chains followed in-message; out-of-zone targets restart from the
      deepest cached zone with full-chain loop detection
    • Fast mode (default) memoizes completed subtrees (completed earlier);
      --fast=false re-walks every branch independently
    • EDNS0 with automatic 512-byte fallback, UDP→TCP retry on truncation, and a
      per-run packet cache so no server is asked the same question twice

    CLI. dnstraverse-style output: refid-numbered progress lines, a
    Results: section of aggregated outcomes with probabilities and dig-style
    records, Summary Results: grouped by status and answer content, optional
    server/version listing, JSON output (--json) as a single deterministic
    document, colour only on a TTY.

    Web interface. The same engine behind a browser SPA and JSON REST API:
    async jobs, live progress over Server-Sent Events (with refid and status per
    event), aggregated results with probabilities, and a one-hour job retention
    window.

    Deployment. Safe to expose publicly by default — hard per-traversal
    timeout (EXPLOREDNS_JOB_TIMEOUT, 5m), concurrent-job cap
    (EXPLOREDNS_MAX_JOBS, 8), CORS off unless EXPLOREDNS_CORS_ORIGIN is set.
    Ships with fly.toml and a tag-triggered deploy workflow; the reference
    deployment runs on Fly.io with machines in Sydney and Virginia.

    Install

    go install gitea.hansenits.com.au/hits/ExploreDNS/cmd/exploredns@v1.0.0
    go install gitea.hansenits.com.au/hits/ExploreDNS/cmd/server@v1.0.0
    
    Downloads